Security and data protection in Google Workspace
All communication between Joan devices, the MyJoan account and the Google Workspace calendar is managed through the official, standard OAuth2 authentication and the Google API with no credentials stored, only access granted.
Outside of the Room Booking feature and the Advanced Analytics feature, no calendar or event information is permanently stored on our servers. In those cases, MyJoan only stores the email of the room's resource. All other information is gained through an API call, parsed and sent directly to the device. This information is temporarily stored in our cache, just to make sure the events are still displayed even if the calendar service experiences a downtime.
When the Room Booking feature is used, calendar events from room calendars are synchronized with our internal database for a rolling window of three months into the future. Events beyond this window are synchronized on demand only when a MyJoan user initiates a calendar action for them. The data collected, how long it is retained, and how to request its deletion are described in the Room booking article.
On the Joan Enterprise subscription plan, certain summarized calendar or event information is stored to enable the Advanced Analytics feature. This includes the first and last name and email of the organizer and attendees, meeting duration, meeting confirmation, and meeting room.
All data we collect and process is encrypted at rest and in transit.
For more detailed information, review our Privacy Policy here or visit the Security page of our website.